Saturday, January 24, 2009

Around The Horn vol.1,19

Alerts

Jan 23, 2009 (13 hours ago)
Monster.com and USAJobs.gov's databases compromised, (Fri, Jan 23rd)

from SANS Internet Storm Center, InfoCON: green
We got a tip from a reader (thanks David!), that apparently Monster.com's database and USAJobs ...(more)...

Security News

9:35 PM (10 hours ago)
Top 10 Mistakes When Crafting a Security RFP, (Fri, Jan 9th)

from SANS Internet Storm Center, InfoCON: green
Creating RFPs for security solutions and processing the responses is not an easy task. Having respon ...(more)...

10:14 PM (9 hours ago)
Monster.com: yet another breach

from CGISecurity - Website and Application Security News by Romain Gaucher
Monster.com has recently experienced yet another breach. "As is the case with many companies that maintain large databases of information, Monster is the target of illegal attempts to access and extract information from its database. We recently learned our database was illegally accessed and certain contact and account data were taken,...

Jan 23, 2009 (20 hours ago)
Pay to install free software

from McAfee Avert Labs by Oliver Devane
I was dealing with customer escalations the other day and came across this interesting sample. If you believe the filename install_wrar380.exe it would install WinRar on your system, for some reason I didn’t believe it .

9:14 PM (10 hours ago)
Monster.com suffers database breach deja vu

from The Register - Security
Millions (more) at risk
For the second time in 18 months, employment search site Monster.com has lost a wealth of personal data belonging to millions of job seekers after its database was illegally accessed.…

Jan 23, 2009 (15 hours ago)
BOFH-loving botmaster wants life as security consultant

from The Register - Security
Feds want him in prison
An American security consultant who stole hundreds of thousands of online bank passwords by employing a massive botnet that he often administered from work deserves at least five years in prison, prosecutors have told a federal judge.…

Jan 23, 2009 (20 hours ago)
TJX closes book on infamous security breach with sale

from The Register - Security
Everything must go
TJX, the discount retailer that was the target of one of the largest information security breaches on record, rewarded customers with a a special sale offering 15 per cent discounts in all its US and Canadian stores on Thursday.…

Jan 23, 2009 (19 hours ago)
Judges grant McKinnon extradition review

from The Register - Security
Gimme shelter
Judges have granted a review of the Home Secretary's decision to continue with extradition proceedings against Pentagon hacker Gary McKinnon.…

Jan 23, 2009 (23 hours ago)
Countdown to Conficker activation begins

from The Register - Security
A superbotnet will rise
Security watchers are bracing themselves to respond to the activitation of the huge botnet created by the Conficker superworm.…

4:58 AM (2 hours ago)
Monster.com reports theft of user data

from Network World on Security
Monster.com is advising its users to change their passwords after data including e-mail addresses, names and phone numbers were stolen from its database.

4:58 AM (2 hours ago)
Conficker hitting hardest in Asia, Latin America

from Network World on Security by Robert McMillan
Computer networks in Asia and Latin America are the most susceptible to a fast-spreading computer worm, which has infected between 6 million and 9 million PCs worldwide, security experts said.

4:58 AM (2 hours ago)
VeriSign buys Certicom after RIM withdraws bid

from Network World on Security
VeriSign said it plans to buy Certicom, just three days after Research In Motion's hostile bid for the security company unraveled.

4:58 AM (2 hours ago)
Fortinet: Holiday season saw spike in Trojan activity, spam

from Network World on Security
The year-end holiday season saw a surge in Trojan activity and spam worldwide, according to network security provider Fortinet.

4:58 AM (2 hours ago)
Gemalto warns against dangerous IT security complacency

from Network World on Security
Digital security firm Gemalto has warned of the risks of the common complacency, across the Asia Pacific, about internet security, despite it being a 'hot region for phishing attacks'.

4:58 AM (2 hours ago)
Social networking sites a hotbed for cyber crime

from Network World on Security
The distribution of malware on social networking sites first occurred in small amounts towards the end of 2007, but that trend appears to be on the rise.

4:58 AM (2 hours ago)
Digital security firm announces Asia expansion

from Network World on Security
Gemalto provides telecommunications, financial services, eGovernment identity and access management, plus IT security and mass transit systems for more than one billion people worldwide. In Singapore, the firm has some 1,000 employees, with 160 engineers engaged in research and development. MIS Asia editor Ross O. Storey, spoke to Ng Fook Seng, Gemalto's Senior Vice-President, Security Business Asia, about the firm's Asia plans.

4:58 AM (2 hours ago)
Downadup/Conflicker worm: When will the next shoe fall?

from Network World on Security by Ellen Messmer
The Downadup worm—also called Conflicker—has now infected an estimated 10 million PCs worldwide, and security experts say they expect to see a dangerous second-stage payload dropped soon.

Jan 23, 2009 (14 hours ago)
Heartland tries to rally industry in wake of data breach

from Network World on Security by Ellen Messmer
The CEO of Heartland Payment Systems is calling for the card payments industry to share security information and consider end-to-end encryption.

4:58 AM (2 hours ago)
Compensation, Data Center Budgets, Social Spammers and More

from Network World on Security
A Call to Tie Pay to Risk

Jan 23, 2009 (14 hours ago)
Researchers wait for Downadup worm's second act

from Network World on Security
The worm that's infected millions of Windows PCs is a "very well-engineered" piece of malware, according to one security expert. But researchers still have no clear idea what the hackers plan to do with the collection of computers they've compromised with "Downadup."

Jan 23, 2009 (14 hours ago)
Amazon cloud could be security hole

from Network World on Security
Cloud services are now vulnerable to malicious use, a security company has suggested, after a techie worked out how Amazon's EC2 service could be used as a BitTorrent file harvester and host.

Jan 23, 2009 (14 hours ago)
F-Secure Internet Security 2009

from Network World on Security
F-Secure Internet Security 2009 (US$60 for three users as of 12/23/08) ranked an unimpressive seventh out of the group of nine in "Paying for Protection," our 2009 roundup of security suites. It started with middling malware detection, and then it slipped further due to its generally slow scan speed and its lack of extra features, such as backup and antiphishing. The suite's reasonably intuitive and easy-to-use interface, as well as its useful startup wizard, weren't enough to outweigh its faults.

Jan 23, 2009 (14 hours ago)
Kaspersky Internet Security 2009

from Network World on Security
Kaspersky Internet Security 2009 was the most expensive security package we tested for "Paying for Protection," our 2009 roundup of nine security suites (US$80 for three users as of 12/23/08). That cost might be justified if the package delivered top-notch performance and a smooth user experience--but it doesn't. Its overall malware-detection rate was below average, and the suite proved aggravating to use in several different scenarios.

Jan 23, 2009 (14 hours ago)
Webroot Internet Security Essentials

from Network World on Security
Webroot's Internet Security Essentials (US$60 for three users as of 12/23/08) marks the antispyware company's first foray into security suites. This patchwork suite brings together an antivirus scanner from Sophos, a firewall from Privacyware, and online backup using Webroot's own servers. But it lacks parental controls, antispam, and browser-based antiphishing capabilities, and it fared poorly at the core task of identifying malicious software.

Jan 23, 2009 (14 hours ago)
Avira Premium Security Suite 8.2

from Network World on Security
Avira Premium Security Suite (US$54 for one user as of 12/23/08) excels where it counts. This package beat the competition in "Paying for Protection," our 2009 roundup of nine security suites, in detection tests, continuing Avira's long history of strong performance in such tests.

Jan 23, 2009 (14 hours ago)
McAfee Internet Security Suite 2009

from Network World on Security
McAfee Internet Security Suite 2009 (US$60 for three users as of 12/23/08) landed smack dab in the middle of the rankings for "Paying for Protection," our 2009 roundup of security suites, ranking fifth out of the nine tested products. The 2009 version features Artemis, a new Internet-based malware detection feature. Offsetting Artemis and McAfee's otherwise generally good malware detection rate, however, were its slow scanning speed, its interface annoyances, and its very poor performance in proactive, behavioral detection tests.

Jan 23, 2009 (14 hours ago)
Trend Micro Internet Security Pro 2009

from Network World on Security
Trend Micro Internet Security Pro 2009 (US$70 for three users as of 12/24/08) fails badly at any security suite's most important task: Identifying malware before it can attack your PC. In tests for "Paying for Protection," our 2009 roundup of nine security suites, Trend Micro's newest offering didn't just come in last place in that crucial category--its dismal 69.3 percent detection rate was a full 20 percentage points behind the next worst competitor. In AV-Test.org's tests, which put each suite up against a huge array of bots, password stealers, and other malware, top performers tagged about 99 percent of the 654,914 samples--but Trend Micro's package let three out of every ten pieces of malicious software go by untouched. That just doesn't cut it for security software.

Jan 23, 2009 (14 hours ago)
Panda Internet Security 2009 Security Software

from Network World on Security
Panda Internet Security 2009 boasts an extensive feature set and an easy-to-use interface, both of which helped it attain a third-place finish in "Paying for Protection," our 2009 roundup of security suites, after Norton Internet Security 2009 and BitDefender Internet Security 2009. But its ability to block malicious software didn't rank as well, and the suite had some genuine difficulty dealing with some especially nasty malware, despite its new Internet-based scanning feature.

Jan 23, 2009 (20 hours ago)
Brief: Obama pledges better cybersecurity, top advisor

from SecurityFocus News
Obama pledges better cybersecurity, top advisor

Jan 23, 2009 (23 hours ago)
“Physicalized” servers may offer virtualization alternative

from Ars Technica by jhruska@arstechnica.com (Joel Hruska)
Server virtualization has become increasingly popular in recent years as a way of improving data center efficiency and lowering IT costs. There are alternatives, however, including what one company is referring to as physicalization.

10:06 PM (9 hours ago)
Monster.com Reports Theft of User Data

from PC World Latest Technology News
Monster.com revealed that information including user e-mails has been stolen from its database.

10:06 PM (9 hours ago)
Conficker Hitting Hardest in Asia, Latin America

from PC World Latest Technology News
Asia and Latin America have been hardest hit by the Conficker worm, security experts say.

Jan 23, 2009 (13 hours ago)
Study: Spam Is Getting More Malicious

from PC World Latest Technology News
Sophos study confirms that, beyond being a major annoyance, spam is even more malicious than ever.

Jan 23, 2009 (13 hours ago)
Mac BitTorrent Users Warned of Trojan

from PC World Latest Technology News
Pirated copies of Apple's iWork 09 software include a most unpleasant surprise.

Jan 23, 2009 (19 hours ago)
Security Software Makers Respond to IWork Trojan Threat

from PC World Latest Technology News
Following Intego's announcement Thursday that pirated copies of iWork '09 may contain a trojan horse, Symantec and...

-- Aurora Report says Monster, Conficker, Cyberczar, and internet security suites reviewed as Mac exposed as virus target too.

Friday, January 23, 2009

Around The Horn vol.1,18

Alerts

5:59 PM (11 hours ago)
TA09-022A: Apple QuickTime Updates for Multiple Vulnerabilities

from US-CERT Technical Cyber Security Alerts
Apple QuickTime Updates for Multiple Vulnerabilities

10:05 PM (7 hours ago)
iWork 2009 Trojan, (Fri, Jan 23rd)

from SANS Internet Storm Center, InfoCON: green
It's already pretty widely reported in the media, take for instance here and here. First reported b ...(more)...

Jan 22, 2009 (19 hours ago)
Unexpected mass reboots are worth investigating, (Thu, Jan 22nd)

from SANS Internet Storm Center, InfoCON: green
An ISC reader told us that his company observed a large number of their PCs unexpectedly reboot at a ...(more)...

Security News

Jan 22, 2009 (15 hours ago)
Security metrics on flaws detected during architectural review?

from CGISecurity - Website and Application Security News by Robert A.
I recently attended a private event where there was a talk on security metrics. Security metrics can be used to determine if action x is reducing risk y. Software security metrics typically involve counting the number of defects discovered over time to see if things are getting better. Most of these...

Jan 22, 2009 (15 hours ago)
PCI Is Meaningless, But We Still Need It

from CGISecurity - Website and Application Security News by Robert A.
There's a good rant at informationweek on PCI."The Heartland Payment Systems breach demonstrates that PCI is bunk. Unfortunately, unless something better comes along, bunk is better than nothing. The PCI compliance program is like a Zen koan: it's a proposition that can't be understood rationally. Unlike a koan, however, pondering on...

Jan 22, 2009 (15 hours ago)
British hacker gang 'tried to steal £229m from Japanese bank'

from CGISecurity - Website and Application Security News by Robert A.
"A six-strong hacker gang attempted to plunder £229million from a Japanese bank in an audacious high-tech scam, a court heard. A crooked security guard at Japanese bank Sumitomo Mitsui let alleged computer hackers into the building in the dead of night where they installed spy software on computers used for multi-million...

Jan 22, 2009 (13 hours ago)
Mac malware piggybacks on pirated iWork

from The Register - Security
Over 20,000 served
Malware masquerading as part of Apple's iWork 09 productivity suite is targeting unsuspecting Mac users foolish enough to install pirated software downloaded on warez sites.…

Jan 22, 2009 (14 hours ago)
Obama unfurls master plan for US cybersecurity

from The Register - Security
Here comes the cyber czar
On his first full-day as US President, Barack Obama on Wednesday outlined plans to declare the country's computer infrastructure a national asset that will be protected by a cyber advisor who will report directly to the president.…

Jan 22, 2009 (22 hours ago)
OcUK puts £10K bounty on the heads of DDoS varmints

from The Register - Security
Wild West response to week-long hack attack
Overclockers.co.uk is offering a £10,000 ($13,830) reward for information leading to the conviction of attackers who have targeted the technology enthusiast site in a DDoS lasting over a week.…

Jan 22, 2009 (13 hours ago)
PBX phone phreakers ring up huge bills in Oz

from The Register - Security
Security loophole allows bad nattering
Phreakers are using security loopholes in PBX systems to make international calls at the expense of businesses in Western Australia.…

5:07 AM (55 minutes ago)
Obama plan says cyber infrastructure is 'strategic'

from Network World on Security by Robert McMillan
The Obama administration has published a high-level plan to protect U.S. computer networks, saying it considers cyber infrastructure "a strategic asset" and will appoint a cyber adviser who will report directly to the president.

5:07 AM (55 minutes ago)
Unisys: Customer convenience key to future IT security

from Network World on Security
Asia Pacific governments and businesses will face pressure during 2009 to 'put the customer first' with their information security strategies, according to information services company Unisys.

5:07 AM (55 minutes ago)
Place your bets against malware

from Network World on Security by Mark Gibbs
The response to my recent Gearhead and Backspin columns on malware has been amazing! And the range of suggestions has ranged from admit defeat, wipe the system, and start again to fight the good fight and don't give in.


5:07 AM (55 minutes ago)
Microsoft Security Response Center gets new boss

from Network World on Security by Robert McMillan
The point man for security bug fixes at Microsoft has stepped down as director of the Microsoft Security Response Center (MSRC).

5:07 AM (55 minutes ago)
Bugs in tech documentation continue to rise

from Network World on Security by Grant Gross
The number of bugs in technical documentation for Microsoft communication protocols continues to grow, according to court documents filed for ongoing antitrust oversight of the company in the U.S.

5:07 AM (55 minutes ago)
Trojan takes 'Office Space' approach to stealing

from Network World on Security by Paul McNamara
Russian security vendor Kaspersky Lab last week began sounding the alarm about an overseas mobile-phone scam that smacks of the movie "Office Space" and may portend future dangers for global users.

5:07 AM (55 minutes ago)
Symbian malware takes money from phone

from Network World on Security by Robert McMillan
Hackers have discovered a new way to steal your money: texting it out of your phone.

Jan 22, 2009 (17 hours ago)
Clerical error foiled Sumitomo bank hack

from Network World on Security
The largest near heist in banking history failed because the men accused of trying to carry it out didn't properly fill in a single field in an electronic transfer form.

5:07 AM (55 minutes ago)
Heartland breach raises questions about PCI standard's effectiveness

from Network World on Security by Ellen Messmer
While it's not yet known if Heartland Payment Systems' data breach will count as the largest card heist ever, some analysts say what is clear is that the Payment Card Industry (PCI) data security standard isn't sufficient.

5:07 AM (55 minutes ago)
Data breach sparks security concerns in payment industry

from Network World on Security
The lack of details surrounding the potentially massive data breach that Heartland Payment Systems Inc. disclosed this week is fueling questions and concerns within the payment processing industry about the exact nature of the security compromise.

Jan 22, 2009 (17 hours ago)
Pirated iWork '09 installer may contain trojan horse

from Network World on Security
Intego, makers of VirusBarrier and other security software for the Macintosh, issued a security alert for Mac users on Thursday, advising them about the existence of a new Trojan Horse, which they've named OSX.Trojan.iServices.A. This new Trojan Horse can be found in pirated copies of Apple's iWork '09 application suite, has been downloaded over 20,000 times, according to Intego's numbers.

Jan 22, 2009 (17 hours ago)
Mac Trojan Horse found in pirated Apple iWork '09

from Network World on Security
Intego, a maker of anti-virus and firewall software, has issued an alert to warn Mac users not to download Apple iWork '09 installers from sites offering pirated software.

Jan 22, 2009 (17 hours ago)
Sophos may lay off up to 5% of staff

from Network World on Security
Security vendor Sophos plans to lay off up to 5% of its staff, the company said Thursday.

3:06 AM (2 hours ago)
CeWL - Custom Word List Generator Tool for Password Cracking

from Darknet - The Darkside by Darknet
It seems to be trendy lately to make tools which can create custom or more specific word lists for password cracking, just last week we posted about the web application The Associative Word List Generator (AWLG), which crawls the whole web to look for associated words with a given topic. This application is more towards creating [...]Read the full post at darknet.org.uk

Jan 22, 2009 (21 hours ago)
Using Twitter for Data Mining and Information Gathering

from Darknet - The Darkside by Darknet
We’ve mentioned Twitter a few times lately as it has become a larger and larger part of the social web and the premier ‘micro-blogging’ platform. There was a recent Phishing issue on Twitter and before that Twitter Jacking and a CSRF bug that allowed auto-following. Due to the large update of Twitter, the amount of datable...Read the full post at darknet.org.uk

Jan 22, 2009 (18 hours ago)
Brief: Apple quashes eight QuickTime flaws

from SecurityFocus News
Apple quashes eight QuickTime flaws

Jan 22, 2009 (18 hours ago)
News: Mac OS X research warns of stealthier attacks

from SecurityFocus News
Mac OS X research warns of stealthier attacks

12:02 AM (6 hours ago)
US cybersecurity ills will be a tough nut for Obama to crack

from Ars Technica by segphault@arstechnica.com (Ryan Paul)
The Obama administration's agenda for boosting homeland security includes a number of issues that relate to cybersecurity. Although the plan reflects an awareness of key security issues posed by emerging technologies, its proposed solutions still need some work.

Jan 22, 2009 (17 hours ago)
An odd choice to help government with open source strategy

from Ars Technica by segphault@arstechnica.com (Ryan Paul)
Obama has asked Sun cofounder Scott McNealy to prepare a paper about the potential cost benefits of adopting open source software in government IT. Although open source adoption would be a smart cost-cutting move, McNealy isn't exactly a fount of wisdom on the subject.

10:13 PM (8 hours ago)
Obama Plan Says Cyber Infrastructure Is 'strategic'

from PC World Latest Technology News
In a new position paper, the Obama administration says it will consider cyber infrastructure a strategic asset.

7:12 PM (11 hours ago)
Symbian Malware Takes Money From Phone

from PC World Latest Technology News
Kaspersky Lab warns that a new mobile-phone Trojan spotted in Indonesia uses SMS messages to steal money.

Jan 22, 2009 (14 hours ago)
Confirmed: Obama gets his BlackBerry, no Sectera Edge in sight

from Engadget by Joshua Topolsky

8:40 PM (10 hours ago)
White House Confirms: President Keeps His Blackberry

from Techdirt by Michael Masnick
There were some stories yesterday saying that, despite earlier worries he'd be forced to give it up, President Obama was able to keep his Blackberry -- and now the White House has confirmed it.

-- Aurora Report says The President has spoken http://www.whitehouse.gov/agenda/homeland_security/.

Thursday, January 22, 2009

Around The Horn vol.1,17

Alerts

Jan 21, 2009 (18 hours ago)
Cisco Unified Communications Manager CAPF Denial of Service Vulnerability

from Cisco Security Advisories
Cisco Unified Communications Manager, formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Certificate Authority Proxy Function (CAPF) service. Exploitation of this vulnerability could cause an interruption in voice services. The CAPF service is disabled by default.

Jan 21, 2009 (18 hours ago)
Cisco Security Manager Vulnerability

from Cisco Security Advisories
Cisco Security Manager contains a vulnerability when it is used with Cisco IPS Event Viewer (IEV) that results in open TCP ports on both the Cisco Security Manager server and IEV client. An unauthenticated, remote attacker could leverage this vulnerability to access the MySQL databases or IEV server.

9:10 PM (9 hours ago)
How to Use Twitter for Information Mining, (Wed, Jan 21st)

from SANS Internet Storm Center, InfoCON: green
Twitter is fun. It's also a powerful research tool ...(more)...

Jan 21, 2009 (14 hours ago)
Vulnerabilities on Cisco and Apple products, (Wed, Jan 21st)

from SANS Internet Storm Center, InfoCON: green
A new set of vulnerabilities has been announced for Cisco and Apple products: Cisco: Cisco S ...(more)...

Jan 21, 2009 (20 hours ago)
Traffic increase for port UDP/8247, (Wed, Jan 21st)

from SANS Internet Storm Center, InfoCON: green
We got reports of a significant traffic increase associated to port UDP/8247 starting yesterday. Tha ...(more)...

Jan 21, 2009 (21 hours ago)
NMAP Trivia ANSWERS: Mastering Network Mapping and Scanning, (Wed, Jan 21st)

from SANS Internet Storm Center, InfoCON: green
Three weeks ago we published the NMAP Trivia challenge. Thanks to all ISC readers that submitted the ...(more)...

Security News

9:21 PM (8 hours ago)
Disabling Windows Autorun - there's a right way and a wrong way

from The Register - Security
Redmond's Downadup protection
After some confusion about exactly how Windows users can protect themselves against a prolific computer worm called Downadup, Microsoft security watchers are once again reiterating the steps for disabling the Autorun feature.…

5:16 AM (1 hour ago)
Sophos to shed one in 20 jobs

from The Register - Security
Redundancies due to shifting priorities, not credit crunch
UK-based security firm Sophos plans to shed five per cent of its workforce as part of a "business reorganisation".…

Jan 21, 2009 (22 hours ago)
The End of Passwords?

from WindowSecurity.com by rickym@trencor.net (Ricky M. Magalhaes)
The end of passwords and how new technologies will keep enterprise information assets secure.

5:07 AM (1 hour ago)
Bloggers wonder: Is Obama's BlackBerry super-encrypted?

from Network World on Security
Bloggers are now speculating that President Barack Obama will have access to a BlackBerry wireless device equipped with a super-encryption package, although -- not surprisingly -- no one is sure whether the president actually is using one.

5:07 AM (1 hour ago)
Blogger: Obama to get 'super-encrypted' BlackBerry

from Network World on Security by John Cox
A blogger for The Atlantic says, without attribution that President Obama will get to use a BlackBerry, one that the NSA has its fingerprints all over, too.

5:07 AM (1 hour ago)
Panda Security: Downadup worm now infects 1 in every 16 PCs

from Network World on Security
The computer worm responsible for the biggest attack in years has infected at least 1 out of every 16 PCs worldwide, a security company said Wednesday, and may have managed to compromise as many as nearly 1 in 3.

Jan 21, 2009 (16 hours ago)
DOJ seeks to block warrantless wiretap ruling

from Ars Technica by julian.sanchez@arstechnica.com (Julian Sanchez)
Just before George W. Bush left office, Justice Department lawyers moved to block a suit challenging warrantless NSA wiretaps.

Jan 21, 2009 (12 hours ago)
DoD Foots the Bill for Web-Based Security Training

from PC World Latest Technology News
Save budgetary bucks by outsourcing security training to our government.

Jan 21, 2009 (12 hours ago)
Debit Card Data Breach Compared to TJX

from PC World Latest Technology News
Banks warn customers about possible fraud, and in one case deactivate 8,500 debit cards.

Jan 21, 2009 (12 hours ago)
Gmail Fills the Bill for Obama Staff

from PC World Latest Technology News
When first entering the White House, Obama's staff lacked e-mail. So, the administration issued its staffers Google Gmail accounts to bridge the gap.

-- Aurora Report says "wow it is a veritable heat wave out there" not that it has anything to do with security but after days of subzero temps today it is a whopping 27 F.

Wednesday, January 21, 2009

Around The Horn vol.1,16

Alerts

Jan 20, 2009 (15 hours ago)
TA09-020A: Microsoft Windows Does Not Disable AutoRun Properly

from US-CERT Technical Cyber Security Alerts
Microsoft Windows Does Not Disable AutoRun Properly

Security News

Jan 20, 2009 (14 hours ago)
Payment Processor Breach May Be Largest Ever

from CGISecurity - Website and Application Security News by Romain Gaucher
The Washington Post reports today a new breach: "A data breach last year at Princeton, N.J., payment processor Heartland Payment Systems may have led to the theft of more than 100 million credit and debit card accounts, the company said today." More info on the article.

Jan 20, 2009 (16 hours ago)
The McAfee 2009 Threat Predictions

from McAfee Avert Labs by David Marcus
Today, we at McAfee Avert Labs released our 2009 Threat Predictions. Amongst the findings are:
Threats Hide in the CloudMiscreants have also transitioned to the Internet “cloud” as their main delivery vehicle and take advantage of the attractions of Web 2.0. McAfee expects this trend to continue throughout 2009, eventually displacing more traditional vectors of malware distribution.

Jan 20, 2009 (20 hours ago)
Fake antivirus and a real threat

from McAfee Avert Labs by Lokesh Kumar
Fake alert malware prey on innocent victims by displaying misleading scan alerts. They trick the user into buying fake antivirus, to fix such falsely exaggerated scan reports. This class of “scareware” software depends on extreme social engineering tactics and comes bundled with Backdoors, Password Stealers, Downloaders, Droppers, Browser Helper Objects, etc.

5:09 AM (1 hour ago)
China's anti-censor software pimps user data

from The Register - Security
Dissident data for sale
Harvard researchers have accused the developers of tools for dodging the Great Firewall of China of selling data harvested by the software, potentially giving the authorities in Beijing an easy way to identify dissidents.…

8:21 PM (10 hours ago)
New OS X research warns of stealthier Mac attacks

from The Register - Security
In-memory code injection covers tracks
A computer security researcher has discovered a new way to inject hostile code directly into the memory of machines running Apple's OS X operating system, a technique that makes it significantly harder for investigators to detect Mac attacks using today's forensics practices.…

Jan 20, 2009 (15 hours ago)
US credit card payment house breached by sniffing malware

from The Register - Security
Suspicious activity in the Heartland
Heartland Payment Systems - a payments processor that serves more than 250,000 US businesses - warned consumers Tuesday that their card data may have been compromised following a security breach of the company's payment system.…

Jan 20, 2009 (17 hours ago)
Call centre manager in the frame over ID scam

from The Register - Security
Alleged two-year dodginess using British identities
An Indian call centre manager is under investigation over allegations he used the identities of Brits to run an insurance fraud scam.…

Jan 20, 2009 (20 hours ago)
McKinnon wins extradition delay

from The Register - Security
All hold pending UK prosecution decision
Gary McKinnon has been granted a delay in his long-running fight against extradition to the US on hacking charges.…

Jan 20, 2009 (21 hours ago)
Conficker Autoplay ruse gets teeth into Windows 7

from The Register - Security
VXers still ahead of the game
Social engineering autoplay tricks work on early versions of Windows 7 as well as Vista, according to tests by security researchers.…

Jan 20, 2009 (23 hours ago)
Conficker seizes city's hospital network

from The Register - Security
Network-wide update ban invites worm infection
Exclusive Staff at hospitals across Sheffield are battling a major computer worm outbreak after managers turned off Windows security updates for all 8,000 PCs on the vital network, The Register has learned.…

Jan 20, 2009 (17 hours ago)
Debit-card processor claims data breach part of global fraud operation

from Network World on Security by Ellen Messmer
Heartland Payment Systems, the Princeton, N.J.-based provider of credit and debit processing, payroll, check management and payments services to more than 250,000 business locations across the country, Tuesday disclosed it was the victim of a security breach.

Jan 20, 2009 (17 hours ago)
Detecting Internet routing "lies"

from Network World on Security by Carolyn Duffy Marsan
Australian Geoff Huston is one of the foremost authorities on Internet routing and scaling issues. We sent Huston a few questions about the U.S. government's plan to bolster R&D to secure the Internet's core routing protocol, the Border Gateway Protocol (BGP). Here are excerpts of from what Huston had to say.

Jan 20, 2009 (17 hours ago)
Embarrassing Insider Jobs Highlight Security, Privacy Holes

from Network World on Security
Officials in San Francisco last summer found out just how easy it can be for one person to hold the city, or at least critical parts of its IT network, hostage for several days. In July, a disgruntled network administrator for the city locked up a multimillion-dollar municipal computer system that handles sensitive data. The employee, Terry Childs, refused to give up the password to the FiberWAN system, which he had helped design. Childs eventually gave the password to San Francisco mayor Gavin Newsom, but not before a lockout that lasted almost two weeks and cost the city close thousands of dollars to fix.

Jan 20, 2009 (17 hours ago)
Microsoft issues patches for 'nasty' Windows bugs

from Network World on Security
Microsoft last week patched three vulnerabilities in the Server Message Block (SMB) file-sharing protocol in Windows, including two that could make "Swiss cheese" out of enterprise networks, according to one researcher.

Jan 20, 2009 (18 hours ago)
Brief: Payment processor warns of network breach

from SecurityFocus News
Payment processor warns of network breach

Jan 20, 2009 (13 hours ago)
Malware infestation responsible for credit card data breach

from Ars Technica by jhruska@arstechnica.com (Joel Hruska)
Heartland Payment Systems announced today that it may have exposed up to 100 million credit and debit cards to theft late last year. This revelation doesn't just set a data breach record, it may explain the surge in credit card fraud we saw last December.

7:44 PM (11 hours ago)
Hackers Imperil 100 Million Credit Card Accounts

from Wired Top Stories by Kim Zetter
Heartland Payment Systems, a company that processes debit- and credit-card transactions for 250,000 businesses, reveals it was hacked late last year and that intruders may have compromised more than 100 million accounts.

Jan 20, 2009 (15 hours ago)
Massive Theft of Credit Card Numbers Reported

from PC World Latest Technology News
Heartland Payment Systems, a payment processor for hundreds of thousands of businesses, disclosed today that it has been hit by what may be the largest credit card data theft to date.

Jan 20, 2009 (18 hours ago)
Smartphone Security Measures

from PC Magazine Tips and Solutions
Even the simplest cell phones carry enough data to be dangerous in the wrong hands.

Jan 20, 2009 (13 hours ago)
Safeguard Your PC Against the Downadup Worm

from PC World Latest Technology News
How to protect your PC from the biggest worm in years.

Jan 20, 2009 (18 hours ago)
A High-Tech Agenda for President Obama

from PC World Latest Technology News
Here's one editor's prescription for high-tech investments, priorities, and -- yes -- legislation.

-- Aurora Report says lions and tigers and bears, oh my!

Tuesday, January 20, 2009

Around The Horn vol.1,15

Alerts

-- No new Security Alerts this morning.

Security News

7:05 PM (11 hours ago)
Single drive wipe protects data, research finds

from CGISecurity - Website and Application Security News by Robert
An article at securityfocus claims a single drive wipe is enough to prevent electron microscopes from recovering drive data."A computer forensics specialist has a message for security-minded computer users: A single wipe will make drives impossible to read. In research published on Thursday, auditor Craig Wright tested the ability of a...

Jan 19, 2009 (14 hours ago)
Safari RSS Reader Vulnerability

from CGISecurity - Website and Application Security News by Robert
In 2006 I gave a talk at blackhat on the risks of RSS vulnerabilities. It appears Safari has a flaw in its RSS reader as outlined by Brian Mastenbrook."The original version of this page contained a simple workaround for this issue which I believed would protect users against this problem. I...

Jan 19, 2009 (20 hours ago)
Shrinking Patch Timelines – The Need For HIPS

from McAfee Avert Labs by Vinoo Thomas
Over the years, the window between exploit discovery to its incorporation into a worm candidate has shrunk from months, to weeks, to zero-day. This leaves administrators with very little time to schedule and deploy patches to all servers and workstations on their network. Virus authors, on the other hand, have been at the cutting edge for including exploit code in their creations whenever a critical vulnerability is reported. The chart below shows the time frame between a vulnerability being reported and how long it took for virus authors to incorporate it into a worm candidate.

6:20 AM (8 minutes ago)
MoD networks still malware-plagued after two weeks

from The Register - Security
Officials: But all our base email are belong to us
Ongoing malware problems at the Ministry of Defence have left some officials and service personnel still without desktop computing, a fortnight after infections began. However, the MoD insists that media reports of its email being sent to Russia are untrue.…

Jan 19, 2009 (13 hours ago)
Three in 10 Windows PCs still vulnerable to Conficker exploit

from The Register - Security
Worm food
Three in ten systems remained unpatched against the exploit fueling the spread of the infamous Conficker worm, according to security tools firm Qualys.…

Jan 19, 2009 (20 hours ago)
Security boffins attempt to freeze out cold boot crypto attack

from The Register - Security
Cache from chaos
Security researchers have developed prototype countermeasures to defend against the recently developed cold boot crypto attack.…

Jan 19, 2009 (22 hours ago)
'Obama quits' spam recruits zombie drones

from The Register - Security
President-Elect heading for office, not Pacific island
Scammers are capitalising on worldwide interest about Barack Obama's inauguration via a spam email campaign that claims the Illinois senator turned prez44 plans to turn down the office he fought so long to obtain.…

6:20 AM (8 minutes ago)
McKinnon's lawyers hope UK prosecution will derail extradition

from The Register - Security
Will change of administration mean change of venue?
Pentagon hacker Gary McKinnon has secured a potential lifeline in his long-running fight against extradition to the US on hacking charges.…

Jan 19, 2009 (16 hours ago)
Fake sites spreading malware claim Obama won't take oath

from Network World on Security
Sites claiming President-Elect Barack Obama will refuse to take the oath of office Tuesday...

9:44 PM (8 hours ago)
Acunetix Web Vulnerability Scanner 6 Review

from Darknet - The Darkside by Darknet
As you might know if you’ve been reading for some time, I do occasionally review commercial software if it’s interesting and relevant - the last one I remember doing was back in 2007 “Outpost Security Suite PRO Review“. This time it’s for a much more relevant piece of software IMHO, and one which I actually like [...]Read the full post at darknet.org.uk

Jan 19, 2009 (17 hours ago)
Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million

from Darknet - The Darkside by Darknet
There hasn’t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it’s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines! It’s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to...Read the full post at darknet.org.uk

9:38 PM (8 hours ago)
DOE report paints bleak picture of our electric future

from Ars Technica by jtimmer@arstechnica.com (John Timmer)
The US Department of Energy has snuck out a report on the future of the US electric grid, one that describes a huge series of challenges that we'll face just to keep the power flowing in the coming decades.
Read More...

7:02 PM (11 hours ago)
DC's CTO prepares for data onslaught on inauguration eve

from Ars Technica by julian.sanchez@arstechnica.com (Julian Sanchez)
Techies in government at CES mull how to protect critical infrastructure—and how DC will deal with the hordes of cell-toting tourists flooding the town for this week's inauguration.
Read More...

Jan 19, 2009 (14 hours ago)
Watch the 2009 Presidential Inauguration without a TV

from Ars Technica by jacqui@arstechnica.com (Jacqui Cheng)
Do you want to watch President-elect Obama's inauguration tomorrow, but don't want to be tied to your TV set? Neither do we. That's why we found a few resources that will let you follow the goings on online and via your mobile phone.
Read More...

Jan 19, 2009 (16 hours ago)
New malware scam claims Obama to resign. Hint: It's not true

from Ars Technica by jhruska@arstechnica.com (Joel Hruska)
Spammers have been taking advantage of President-elect Obama's imminent election over the past few days, but they aren't capitalizing on the excitement surrounding his election. Instead, the authors are spreading rumors that Obama has quit altogether.
Read More...

Jan 19, 2009 (22 hours ago)
Building desktop Linux applications with JavaScript

from Ars Technica by segphault@arstechnica.com (Ryan Paul)
Ars takes a close look at Seed, a new framework that allows software developers to build GTK+ applications with JavaScript. The popular web scripting language could soon become the dominant application extension language on the Linux desktop.
Read More...

1:06 AM (5 hours ago)
Citrix Plans 'bare Metal' Desktop Hypervisor

from PC World Latest Technology News
Citrix Systems is working with Intel to deliver a "bare metal" hypervisor for client PCs, which proponents say could broaden...

Jan 19, 2009 (12 hours ago)
Feds to Shore Up Net Security

from PC World Latest Technology News
In an effort to prevent routing hijack attacks, the U.S. government is ramping up its move to secure the Internet's routing system

12:51 AM (5 hours ago)
Smartphone Security Measures

from PC Magazine Tips and Solutions
Even the simplest cell phones carry enough data to be dangerous in the wrong hands.

-- Aurora Report says time to go work out, extra content courtesy of extra probing due to lack of alerts.

Monday, January 19, 2009

Around The Horn vol.1,14

Alerts

Jan 18, 2009 (12 hours ago)
DNS queries for ".", (Sun, Jan 18th)

from SANS Internet Storm Center, InfoCON: green
Several folks are reporting odd queries hitting their DNS servers at a steady rate of about two per ...(more)...

7:36 AM (6 minutes ago)
3322. org, (Sun, Jan 18th)

from SANS Internet Storm Center, InfoCON: green
Earlier today, an ISC reader sent us a looong capture of what looked like a buffer overflow attack. ...(more)...

Security News

5:07 AM (2 hours ago)
Hotspot horrors

from Network World on Security by James E. Gaskin
Laptops are the main business tool for most mobile workers, and connecting those devices to the Internet via free public Wi-Fi hotspots has become common practice. So how well do your mobile workers follow security guidelines for safe mobile computing?

5:07 AM (2 hours ago)
Fake sites spreading malware claim Obama won't take oath

from Network World on Security
Sites claiming President-Elect Barack Obama will refuse to take the oath of office Tuesday are serving up attack code believed to be programmed by the same hackers responsible for the notorious Storm bot Trojan, researchers said this weekend.

10:59 PM (8 hours ago)
YouTube begins experimenting with downloadable videos

from Ars Technica by david@arstechnica.com (David Chartier)
Tools for grabbing videos from YouTube have existed for some time now, but Google's video portal began experimenting this weekend with allowing users to download a high-quality H.264 version directly from a video's site. The feature appeared first on the Obama campaign's ChangeDotGov account, and it is expected to roll out to the rest of YouTube users in the coming weeks.

Jan 18, 2009 (12 hours ago)
IRS Taxpayer Data is Insecure

from PC World Latest Technology News
Two audits suggest the IRS needs to clean up its network access and secure taxpayer data.

Jan 18, 2009 (18 hours ago)
Securing the Presidential BlackBerry

from PC World Latest Technology News
Security efforts explain how the military-level encryption and restricted use could enable Obama to keep his handheld.

-- Aurora Report says quality not quantity: Learn how to dive deep into a buffer overflow attempt, what's up with free wi-fi, irs follies and blackbery security - not a bad start to the week.

Sunday, January 18, 2009

Around The Horn vol.1,13

Alerts

5:07 AM (3 hours ago)
Targeted social engineering, (Sun, Jan 18th)

from SANS Internet Storm Center, InfoCON: green
Heres a somewhat dated and simplified graph of the three main attack modus operandiquo ...(more)...

Security News

Jan 17, 2009 (21 hours ago)
Don’t worry, Obama did not refuse to be a president!

from McAfee Avert Labs by Francois Paget
In less than four days the inauguration of President-Elect Barack Obama will make headlines. At McAfee, we expect cybercriminals to use this event to conduct their typical attacks like they do when the news gives them such opportunity.
Unfortunately, we were right and some sites have already started to circulate fake information on this subject to lure in the crowds in an attempt to infect their computers. Here is one of them we recently discovered. As you can see for yourself this author does not hesitate to make use of sensationalism:

-- Aurora Report says OMG that's it, that's all, well alrighty then.

My Blog List